Show HN: A web-based matrix client: Cinny
github.com
github.com
__________
EDIT: Upon registration "Password must contain 1 number, 1 uppercase letters, 1 lowercase letters, 1 non-alpha numeric number, 8-16 characters with no space."
Not sure if that's a Matrix limitation or just javascript validation, but if it's on your end please don't do that... if anything you're enforcing less secure passwords.
__________
EDIT 2: Hitting reload on https://app.cinny.in/register leads to a 404
https://matrix.org/docs/spec/client_server/latest#notes-on-p...
> Clients SHOULD enforce that the password provided is suitably complex. The password SHOULD include a lower-case letter, an upper-case letter, a number and a symbol and be at a minimum 8 characters in length. Servers MAY reject weak passwords with an error code M_WEAK_PASSWORD.
The criteria that I think would be acceptable to be enforced includes:
- A maximum (not a minimum) length, which must be suitably long, perhaps 200 bytes (or longer).
- Rejecting passwords containing null bytes.
- Rejecting passwords containing sequences of bytes that cannot be transmitted using the protocol, if it is necessary to transmit the password using the protocol at all (which it might not be, since it might use a hash instead). (This depends on the protocol.)
- If despite the advice above, the client knows that the server will reject other passwords too, and knows precisely what the criteria are, the client can reject the same passwords.
Examples of some things that should be allowed (and should not be rejected) include:
- Passwords that are short.
- Passwords that include your username as a substring.
- Character classes/lack of character classes (e.g. you should not require nor prohibit punctuation).
- Control characters (if not causing problems with the protocol like mentioned above).
- Invalid UTF-8 sequences.
(Just because they are allowed though, does not necessarily mean that they should be recommended.)
Also, passwords should always be case-sensitive.
The user should decide by themself what password they want to set, although it is OK to include advice that is optional.
As for the other requirements, it's just a matter of enabling various options in your password manager's generator. And if you're not using a password manager, it's very probable you're using/reusing insecure passwords.
congratulations, it’s no longer a secure password
"Password must contain 1 number, 1 uppercase letters, 1 lowercase letters, 1 non-alpha numeric number, 8-16 characters with no space."
Even an example password:
apPa4SRODhLWcUa/x9HbqA==
which passes all the requirements doesn't work.
I would really like to use this.
But if you go to the homepage (index.html) and click on Login it will do the weird little SPA routing thing and load the page correctly.
I'm guessing netlify needs to route every URL path to the index.html?
SPA apps have just fundamentally broken the web.
More substantively: the look of this is so nice. My biggest complaint with element is UX around cross-signing (though I'd also switch in a heartbeat if someone hacked in voice messages somehow). How have you found all that to implement? (Totally fine if it's still on a roadmap, I'm just curious)
I also tried changing the "light" in the url to "dark" and got https://cinny.in/assets/preview-dark.png
Image:
It would also be interesting to know a little bit more how the hard features are implemented. Key exchange and cross signing in E2EE? Plans for "native" VoIP?
(it looks like cinny is built on matrix-js-sdk, which also powers element web, so inherits the e2ee support and could inherit voip etc from there).
It does lack a lot of basic features though (like reply, editing/deleting messages, ...).
Totally understandable, of course, but React apps always tend to be fast early on but slow down as more and more features are added.
This is hands down my biggest pet peeve with so many open source projects and an outright reason I won't use some of them.
Amazing job.
The app is really impressively well done - goes to show how well an entirely fresh React app can run on top of matrix-js-sdk (and thus how much snappier Element can be :)
If it is any consolation, Mozilla (yes, that Mozilla!) moved over from irc to matrix back in 2020 if i recall correctly. So, i imagine that would represent a large-ish number of irc users, and many likely had been using irc for quite some time now. See: https://discourse.mozilla.org/t/synchronous-messaging-at-moz... and https://wiki.mozilla.org/IRC
The validation on the login page is a bit annoying though. I'd like to paste a Matrix address like @username:domain.org.
It would be cool if this limitation was a little more up front - While I can spin up a copy on my own and adjust the limitation myself, I don't think everyone's going to want to do that.
I hope that helps!
I'm definitely sold and following along with developments
Looking forward to trying this out later today.
Nice work!
matrix.org
Then I'm guessing it has a captcha. I'm not sure because it fails to load with Privacy Badger enabled.
My attention just wandered away. Hopefully they can address some basic privacy concerns and get another at-bat.
Edit: Seems that matrix.org is now requiring an email address.
any plans for mobile? maybe give react native and react-native-web a try!
Until then, it does support Reply messages similar to Discords.